CVE-2024-3366: Xuxueli Xxl-Job
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.
Affected products
- Xuxueli Xxl-Job: before 2.4.1 (fixed in 2.4.1)
Published 2024-04-06. Last modified 2026-06-17.